
Certified Cybersecurity Operations Analyst
Domain 2Objective 3
Cybersecurity Architecture CCOA Practice Questions (Page 1)
Part of the Domain 2: Cybersecurity Principles and Risk domain, which accounts for 20% of the CCOA exam. ISACA does not publish an official question count, but from its 240-minute exam (~95–160 total, ~19–32 in this domain), expect 5–8 from this objective — we provide 45 practice questions to prepare you well beyond it. (estimate)
45questions here
9free pages
14concepts
20%of the exam
Questions 1–5
- 1
A security analyst is investigating a breach where an attacker first sent a phishing email, then exploited a vulnerability, installed malware, and finally exfiltrated data. The analyst wants to map these actions to stages of an attack lifecycle. Which framework should they use?
Select an answer first - 2
Which of the following is NOT one of the five core functions of the NIST Cybersecurity Framework (CSF)?
Select an answer first - 3
A defense contractor processes classified documents on a system where users have different clearance levels. The security team must prevent users with lower clearance from reading higher-classified documents, but they are less concerned about unauthorized writes to higher-classified files. Which model best fits this requirement?
Select an answer first - 4
Which security goal is primarily concerned with ensuring that data has not been altered or tampered with by unauthorized parties?
Select an answer first - 5
A security operations center (SOC) is using MITRE ATT&CK to improve detection capabilities. They have identified that attackers are using PowerShell for execution and lateral movement. The SOC wants to prioritize detections that cover these techniques. Which approach best leverages ATT&CK for this purpose?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CCOA” is a trademark of its owner, used for identification only.